Cisco Nexus Dashboard Orchestrator vulnerabilities

4 known vulnerabilities affecting cisco/cisco_nexus_dashboard_orchestrator.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-20490HIGHCVSS 8.6v1.0(1i)v1.0(2b)+23 more2024-10-02
CVE-2024-20490 [MEDIUM] CWE-200 CVE-2024-20490: A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Ne A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log that is stored in the tech suppor
cvelistv5nvd
CVE-2024-20385MEDIUMCVSS 5.9v3.7(1d)v3.7(1g)+20 more2024-10-02
CVE-2024-20385 [MEDIUM] CWE-295 CVE-2024-20385: A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allo A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated, remote attacker to intercept sensitive information from an affected device. This vulnerability exists because the Cisco NDO Validate Peer Certificate site management feature validates the certificates for Cisco Application Polic
cvelistv5nvd
CVE-2024-20281HIGHCVSS 8.8vN/A2024-04-03
CVE-2024-20281 [HIGH] CWE-352 CVE-2024-20281: A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashb A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an aff
cvelistv5nvd
CVE-2024-20302MEDIUMCVSS 4.3vN/A2024-04-03
CVE-2024-20302 [MEDIUM] CWE-284 CVE-2024-20302: A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) co A vulnerability in the tenant security implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an authenticated, remote attacker to modify or delete tenant templates on an affected system. This vulnerability is due to improper access controls within tenant security. An attacker who is using a valid user account with write privileges
cvelistv5nvd